Smart Contract Audit

Runtime Monitoring

Index

FIU-IND Guidelines for VDAs: India Crypto Compliance

Introduction

India’s regulatory framework for Virtual Digital Assets (VDAs) continues to mature in 2026, making FIU-IND (Financial Intelligence Unit–India) compliance a critical requirement for cryptocurrency exchanges, wallet providers, tokenization platforms, and other Virtual Asset Service Providers (VASPs). Under the Prevention of Money Laundering Act (PMLA), businesses dealing with virtual digital assets must register with FIU-IND and implement robust Anti-Money Laundering (AML) and Counter-Terrorism Financing (CFT) controls to operate legally.

As regulatory scrutiny increases and global compliance standards continue to evolve, startups must go beyond basic registration by adopting comprehensive KYC, transaction monitoring, record-keeping, and risk management practices. Understanding the latest FIU-IND guidelines not only helps organizations avoid regulatory penalties but also strengthens investor confidence, improves operational transparency, and supports long-term business growth in India’s rapidly expanding digital asset ecosystem.

What Activities Do FIU-IND Guidelines Cover?

The FIU-IND rules apply to businesses that offer specific virtual asset services on behalf of customers.
In March 2023, the government clarified that the following activities fall under PMLA for virtual digital assets:

  • Exchange services: Converting virtual digital assets to fiat currency, or vice versa.
  • Crypto-to-crypto trading: Swapping one virtual asset for another.
  • Transfers: Sending or receiving virtual digital assets, whether custodial or non-custodial.
  • Custody or safekeeping: Holding or administering virtual assets or related instruments.
  • Token issuance services: Providing financial services related to the sale of a virtual asset.

A virtual digital asset, as defined in the Income Tax Act, 1961, includes cryptocurrencies, NFTs, and similar tokens.
In practice, any platform that allows buying, selling, transferring, or holding crypto assets for customers must follow FIU-IND rules.

Why the FIU-IND Guidelines Matter

FIU-IND guidelines bring crypto businesses into India’s official AML framework. Under PMLA, FIU-IND can issue and enforce rules for reporting entities.
The notice states that virtual asset service providers must follow all PMLA provisions, including:

  • Customer due diligence
  • Suspicious transaction reporting
  • Internal AML controls
  • Record-keeping

Registration with FIU-IND is mandatory. Failure to register is itself a violation under Section 13(2) of PMLA and can lead to enforcement action.
In short, crypto startups must join the reporting entity system or face penalties.

Key Compliance Requirements for Virtual Asset Providers

To meet FIU-IND requirements, a virtual asset business must complete several steps.

1. Register with FIU-IND

Registration happens through the FINET 2.0 portal. However, it is only complete after an in-person interview with FIU-IND officials. Both the Designated Director and Principal Officer must attend.

2. Attend FIU-IND Review Meeting

Officials review the business model and documents to confirm that the company falls under the notified virtual asset activities.

3. Submit Corporate and Financial Documents

Businesses must provide:

  • Incorporation certificates
  • Annual returns
  • Audited financial statements for the last three years

4. Provide Tax and State Registrations

This includes:

  • GST registration certificate
  • GST returns for the last three years
  • Income tax returns
  • TDS statements (Forms 26Q/26QF/26QE) related to VDA transactions

5. Detail Business Relationships

If the platform works with other entities, Indian or foreign, for exchange or custody, it must submit agreements showing these partnerships.

6. Confirm Integrity and Compliance

Companies must submit a self-declaration confirming no pending enforcement actions.
If partnered with a registered virtual asset provider, the company must also provide a “Fit and Proper” certificate from that partner.

7. Complete FIU-IND Questionnaires

FIU-IND may require AML/CFT questionnaires. Startups must provide detailed explanations of their policies and procedures.

8. Sign Official Undertakings

Directors, Principal Officers, and Compliance Officers must sign undertakings agreeing to follow PMLA and FIU-IND rules.

By completing these steps, a business shows that it maintains strong KYC/AML controls and transparent processes. FIU-IND can deny or revoke registration if obligations are not met.

Implications of Non-Compliance

Ignoring FIU-IND rules can lead to serious outcomes.
Under Section 13(2) of PMLA, FIU-IND can:

  • Freeze assets
  • Impose fines
  • Attach proceeds of crime
  • Initiate prosecution

Operating without registration is already a violation.
Beyond legal penalties, non-compliance hurts reputation. Investors prefer startups that follow regulations and maintain clear audit trails.
Compliance builds trust. Non-compliance drives customers and partners away.

Why AML/CFT Compliance Matters

FIU-IND guidelines highlight the need for strong AML/CFT practices. Virtual asset businesses must:

  • Perform KYC on all users
  • Monitor transactions
  • Report suspicious activities
  • Maintain logs and records for at least five years

These records include wallet addresses, transaction history, and KYC documents.

How SecureDApp Helps Startups Stay Compliant

SecureDApp simplifies compliance for crypto businesses. It provides:

  • Automated KYC/KYB checks
  • AML transaction monitoring
  • Documentation management
  • Audit trails
  • Alignment with FIU-IND documentation requirements

With SecureDApp, startups can meet FIU-IND expectations while focusing on growth.

Frequently Asked Questions

1. Who needs to register with FIU-IND under India’s VDA regulations?

Any Virtual Asset Service Provider (VASP) offering services such as cryptocurrency exchanges, custodial wallets, crypto transfers, token issuance, or digital asset custody on behalf of customers must register with FIU-IND and comply with PMLA requirements.

2. What are the key AML obligations for crypto businesses under FIU-IND?

Registered entities must perform customer due diligence (KYC), monitor transactions for suspicious activities, maintain transaction records, file Suspicious Transaction Reports (STRs) when required, implement internal AML/CFT controls, and retain compliance records according to regulatory requirements.

3. What are the consequences of failing to comply with FIU-IND regulations?

Non-compliance may result in regulatory investigations, monetary penalties, suspension of operations, enforcement actions under the Prevention of Money Laundering Act (PMLA), reputational damage, and difficulties in establishing banking and institutional partnerships.

4. How can crypto startups simplify FIU-IND compliance?

Businesses can streamline compliance by implementing automated KYC/KYB verification, continuous AML transaction monitoring, risk-based customer screening, secure record management, periodic compliance audits, and comprehensive documentation systems that align with FIU-IND reporting requirements.

5. How does SecureDApp support FIU-IND compliance for Web3 businesses?

SecureDApp helps Virtual Asset Service Providers meet regulatory obligations through automated KYC/KYB verification, AML monitoring, compliance documentation management, audit-ready reporting, smart contract security assessments, and continuous monitoring solutions that simplify compliance while strengthening overall blockchain security.

Quick Summary

This blog outlines FIU-IND's PMLA guidelines mandating registration, KYC, AML monitoring, and reporting for India's VDA exchanges, wallets, and token services. Crypto startups and investors master compliance steps like FINET 2.0 filings, document submissions, review meetings, plus SecureDApp tools to avoid fines and build trust.

Related Posts

What Is a Data Fiduciary Under India’s DPDP Act and What Are Your Obligations
19May

What Is a Data Fiduciary…

The Law Has Changed. Has Your Platform? India’s Digital Personal Data Protection Act, 2023 is no longer just a policy discussion. It is active law, and organizations handling personal data are being held to a new standard. At the center of this law sits one critical concept:…

FATF Travel Rule: Crypto & DApp Compliance Guide
25Nov

FATF Travel Rule: Crypto &…

This blog breaks down the FATF Travel Rule for crypto transfers over $1,000, mandating VASP data sharing like names and wallet addresses. DApp developers and founders learn compliance hurdles in decentralization, KYC integration, plus SecureDApp tools for automated triggers, encrypted handling, and cross-chain alignment via case studies…

Blockchain Endpoint Security: API & UI Vulnerabilities
24Nov

Blockchain Endpoint Security: API &…

This blog examines blockchain endpoint vulnerabilities in UIs and APIs, such as broken authentication, insecure private key storage, and excessive data exposure that enable hacks like the 2022 $500M exchange breach. Developers learn defense-in-depth strategies including SecureDApp MFA, encryption, input validation, and object-level authorization to secure user-blockchain…

Tell us about your Projects